Newsroom

European offensive cybersecurity: Fleuret.AI raises 4 M€

yanis-grigy-fleuret-ai-actu
The French startup Fleuret.AI, co-founded by Yanis Grigy, a student at Télécom Paris, aims to transform pentesting—which is still largely viewed as a one-time audit—into a continuous security activity. Its first funding round of 4 million euros will enable the company to accelerate its work on artificial intelligence for cybersecurity on an European scale.
Fleuret.AI, entrepreneurship & fundraising (video)

Yanis Grigy, student at Télécom Paris, presents Fleuret.AI, an innovative startup that has just raised 4 million euros to automate pentesting using AI and build an European offensive cybersecurity capability. Thomas Houy, associate professor in management, tells us about Télécom Paris’ entrepreneurship program, which enabled Yanis to bring his first project to fruition.

Video Michel Desnoues

Five questions to Yanis Grigy

What is your business?

Fleuret.AI performs autonomous offensive penetration testing (pentesting) using agent-based artificial intelligence to strengthen European sovereignty. The engine, named Émile, conducts the attack from start to finish, including reconnaissance, exploitation, a reproducible proof of concept, and an audit report. We test web apps, APIs, and external infrastructure, as well as cloud environments, Active Directory, and mobile devices.

Our business model involves delivering an audit to the client within a few hours at a cost of €4,000 per scope, with zero false positives tolerated (findings mapped to NIS2 / DORA / ISO 27001); whereas a typical firm takes two to four weeks to deliver a report starting at €10,000, once or twice a year, resulting in three to twelve months of unmonitored exposure between audits.

Where are you at?

Our product is “live” and in production at several major clients, in real-world environments—not just lab pilots. The team is growing quickly: we now have eleven people across engineering, offensive security, and sales, with team members who have backgrounds in European cybersecurity. Our current focus is on expanding product coverage and establishing our distribution model: Customers use Fleuret as part of the compliance workflow they already have in place.

As a result, we are now operating on an international scale through this channel, with European platform partners. We host our data in Europe, which is a decisive factor in terms of DORA and NIS2.

What is the background of this funding round?

It is a €4 million seed round led by RAISE Capital, alongside Auriga Cyber Ventures, Wind Capital, and Better Angle, supplemented by a group of business angels who are European cybersecurity industry leaders (founders of Almond, GitGuardian, Stoïk, OVRSEA, and Hornetsecurity).

What the raise changes

The goal isn’t to sell more pentests; it’s to help our clients transition to a true posture of continuous security. Agent-based pentesting is the entry point; the value comes from the additional components built around it: automated retesting after patches are applied, tracking remediation in the team’s tools, continuous mapping of findings to NIS2, DORA, and ISO 27001, and progressive coverage of scopes that are still missing (cloud, Active Directory, mobile).

This funding round will finance these building blocks, the associated hiring, and the launch on the European market: direct sales to CISOs, CTOs, and DPOs, as well as partnerships with cyber insurance providers and consulting firms, supported by an European infrastructure. The regulatory timeline supports this funding round: NIS2 entity registration by the end of 2026, initial audits in 2027, and 10,000 to 15,000 French entities affected in France.

How has your curriculum at Télécom Paris helped you launch this venture?

The Télécom Paris ecosystem enabled us to get our first pentesting company off the ground. Two resources were equally important. On the technical side, we had access to labs, faculty members, and a community of security engineers. On the business side, Télécom Paris’ incubator gave us access to a pool of startups already undergoing ISO 27001 and SOC2 certification processes—in other words, real buyers with an immediate need. As a result, three of our clients signed up thanks to the Télécom Paris incubator, and they served as our first references and provided a testing ground for our product.